ironic@38.0.0

OpenStack Bare Metal Provisioning

Direct Vulnerabilities

Known vulnerabilities in the ironic package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Arbitrary Code Injection

ironic is an OpenStack Bare Metal Provisioning

Affected versions of this package are vulnerable to Arbitrary Code Injection via the boot script processing. An attacker can execute arbitrary commands on affected systems by injecting malicious scripts during the boot process.

How to fix Arbitrary Code Injection?

A fix was pushed into the master branch but not yet published.

[17.0.0,)
  • M
Insertion of Sensitive Information Into Sent Data

ironic is an OpenStack Bare Metal Provisioning

Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the PATCH process on volume properties. An attacker can obtain sensitive information by sending a PATCH request to update volume properties they are authorized for, which may result in the exposure of unredacted confidential data such as iSCSI credentials.

How to fix Insertion of Sensitive Information Into Sent Data?

A fix was pushed into the master branch but not yet published.

[17.0.0,)